CVE-2014-1492

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
mozillanetwork_security_services
𝑥
≤ 3.15.5
mozillanetwork_security_services
3.2
mozillanetwork_security_services
3.2.1
mozillanetwork_security_services
3.3
mozillanetwork_security_services
3.3.1
mozillanetwork_security_services
3.3.2
mozillanetwork_security_services
3.4
mozillanetwork_security_services
3.4.1
mozillanetwork_security_services
3.4.2
mozillanetwork_security_services
3.5
mozillanetwork_security_services
3.6
mozillanetwork_security_services
3.6.1
mozillanetwork_security_services
3.7
mozillanetwork_security_services
3.7.1
mozillanetwork_security_services
3.7.2
mozillanetwork_security_services
3.7.3
mozillanetwork_security_services
3.7.5
mozillanetwork_security_services
3.7.7
mozillanetwork_security_services
3.8
mozillanetwork_security_services
3.9
mozillanetwork_security_services
3.11.2
mozillanetwork_security_services
3.11.3
mozillanetwork_security_services
3.11.4
mozillanetwork_security_services
3.11.5
mozillanetwork_security_services
3.12
mozillanetwork_security_services
3.12.1
mozillanetwork_security_services
3.12.2
mozillanetwork_security_services
3.12.3
mozillanetwork_security_services
3.12.3.1
mozillanetwork_security_services
3.12.3.2
mozillanetwork_security_services
3.12.4
mozillanetwork_security_services
3.12.5
mozillanetwork_security_services
3.12.6
mozillanetwork_security_services
3.12.7
mozillanetwork_security_services
3.12.8
mozillanetwork_security_services
3.12.9
mozillanetwork_security_services
3.12.10
mozillanetwork_security_services
3.12.11
mozillanetwork_security_services
3.14
mozillanetwork_security_services
3.14.1
mozillanetwork_security_services
3.14.2
mozillanetwork_security_services
3.14.3
mozillanetwork_security_services
3.14.4
mozillanetwork_security_services
3.14.5
mozillanetwork_security_services
3.15
mozillanetwork_security_services
3.15.1
mozillanetwork_security_services
3.15.2
mozillanetwork_security_services
3.15.3
mozillanetwork_security_services
3.15.3.1
mozillanetwork_security_services
3.15.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nss
bullseye
2:3.61-1+deb11u3
fixed
bullseye (security)
2:3.61-1+deb11u4
fixed
bookworm
2:3.87.1-1
fixed
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
trusty
dne
saucy
not-affected
quantal
not-affected
precise
not-affected
lucid
not-affected
firefox
trusty
Fixed 29.0+build1-0ubuntu0.14.04.2
released
saucy
Fixed 29.0+build1-0ubuntu0.13.10.3
released
quantal
Fixed 29.0+build1-0ubuntu0.12.10.3
released
precise
Fixed 29.0+build1-0ubuntu0.12.04.2
released
lucid
ignored
nss
trusty
Fixed 2:3.15.4-1ubuntu7
released
saucy
Fixed 2:3.15.4-0ubuntu0.13.10.2
released
quantal
Fixed 3.15.4-0ubuntu0.12.10.2
released
precise
Fixed 3.15.4-0ubuntu0.12.04.2
released
lucid
Fixed 3.15.4-0ubuntu0.10.04.2
released
oxide-qt
trusty
dne
saucy
dne
quantal
dne
precise
dne
lucid
dne
thunderbird
trusty
dne
saucy
ignored
quantal
ignored
precise
not-affected
lucid
ignored
References